M. A. Nugroho, Sidik Prabowo, Mas'ud Adhi Saputra, M. Abdurohman
{"title":"可编程数据平面的端口敲打实现","authors":"M. A. Nugroho, Sidik Prabowo, Mas'ud Adhi Saputra, M. Abdurohman","doi":"10.1109/ICTS52701.2021.9608629","DOIUrl":null,"url":null,"abstract":"This paper proposes the port knocking method to offload the network functions on Software-Defined Networks to programmable data plane. The main drawback of centralized SDN controller architecture is causing bottlenecks in the network because every packet that arrives at the switch must be forwarded to the controller first. The controller will decide whether the packet is allowed to be forwarded or dropped, resulting in increased processing delay for packet processing. There are several previous methods have been proposed. However, they could not meet the need of network performance. Thus, we decide to migrate the several controller functions in the data plane. This paper presents port knocking (PkoCK) implementation in programmable data plane. PKock successfully offloads the port knocking implementation to the data plane and reduces the processing delay 19% compared to SDN-based port knocking.","PeriodicalId":6738,"journal":{"name":"2021 13th International Conference on Information & Communication Technology and System (ICTS)","volume":"26 1","pages":"35-39"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Port Knocking Implementation on Programmable Data Plane\",\"authors\":\"M. A. Nugroho, Sidik Prabowo, Mas'ud Adhi Saputra, M. Abdurohman\",\"doi\":\"10.1109/ICTS52701.2021.9608629\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper proposes the port knocking method to offload the network functions on Software-Defined Networks to programmable data plane. The main drawback of centralized SDN controller architecture is causing bottlenecks in the network because every packet that arrives at the switch must be forwarded to the controller first. The controller will decide whether the packet is allowed to be forwarded or dropped, resulting in increased processing delay for packet processing. There are several previous methods have been proposed. However, they could not meet the need of network performance. Thus, we decide to migrate the several controller functions in the data plane. This paper presents port knocking (PkoCK) implementation in programmable data plane. PKock successfully offloads the port knocking implementation to the data plane and reduces the processing delay 19% compared to SDN-based port knocking.\",\"PeriodicalId\":6738,\"journal\":{\"name\":\"2021 13th International Conference on Information & Communication Technology and System (ICTS)\",\"volume\":\"26 1\",\"pages\":\"35-39\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-10-20\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 13th International Conference on Information & Communication Technology and System (ICTS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICTS52701.2021.9608629\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 13th International Conference on Information & Communication Technology and System (ICTS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICTS52701.2021.9608629","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Port Knocking Implementation on Programmable Data Plane
This paper proposes the port knocking method to offload the network functions on Software-Defined Networks to programmable data plane. The main drawback of centralized SDN controller architecture is causing bottlenecks in the network because every packet that arrives at the switch must be forwarded to the controller first. The controller will decide whether the packet is allowed to be forwarded or dropped, resulting in increased processing delay for packet processing. There are several previous methods have been proposed. However, they could not meet the need of network performance. Thus, we decide to migrate the several controller functions in the data plane. This paper presents port knocking (PkoCK) implementation in programmable data plane. PKock successfully offloads the port knocking implementation to the data plane and reduces the processing delay 19% compared to SDN-based port knocking.